Scanner: Docker Scout
Critical vulnerabilities: 2
High vulnerabilities: 15
Medium vulnerabilities: 7
Critical
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-45833 | chromadb | 0.5.20 | not fixed | CVE-2026-45833: Improper Control of Generation of Code ('Code Injection') |
| CVE-2026-39821 | stdlib | 1.26.5 | 1.26.6 | CVE-2026-39821 |
High
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-33818 | stdlib | 1.26.5 | 1.26.6 | CVE-2026-33818 |
| CVE-2026-46600 | stdlib | 1.26.5 | 1.26.6 | CVE-2026-46600 |
| CVE-2026-56853 | stdlib | 1.26.5 | 1.26.6 | CVE-2026-56853 |
| CVE-2026-56855 | crypto | 0.55.0 | 0.56.0 | CVE-2026-56855 |
| CVE-2026-56859 | stdlib | 1.26.5 | 1.26.6 | CVE-2026-56859 |
| CVE-2026-56862 | stdlib | 1.26.5 | 1.26.6 | CVE-2026-56862 |
| CVE-2026-57585 | msgpack | 1.1.2 | 1.2.1 | CVE-2026-57585 |
| CVE-2026-78662 | crypto | 0.55.0 | 0.56.0 | CVE-2026-78662 |
| GHSA-6v7p-g79w-8964 | msgpack | 1.1.2 | 1.2.1 | GHSA-6v7p-g79w-8964: Use After Free |
| CVE-2025-47273 | setuptools | 70.3.0 | 78.1.1 | CVE-2025-47273: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-81726 | nltk | 3.10.3 | not fixed | CVE-2026-81726: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2026-84304 | grpc | 1.83.0 | 1.83.1 | CVE-2026-84304: Uncontrolled Resource Consumption |
| CVE-2026-84445 | grpc | 1.83.0 | 1.83.2 | CVE-2026-84445: Improper Validation of Array Index |
| CVE-2026-45830 | chromadb | 0.5.20 | not fixed | CVE-2026-45830: Incorrect Privilege Assignment |
| CVE-2026-45831 | chromadb | 0.5.20 | not fixed | CVE-2026-45831: Incorrect Authorization |
Medium
| CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|
| CVE-2026-85999 | soupsieve | 2.8.4 | 2.9.0 | CVE-2026-85999: Inefficient Regular Expression Complexity |
| CVE-2026-86000 | soupsieve | 2.8.4 | 2.9.0 | CVE-2026-86000: Inefficient Regular Expression Complexity |
| CVE-2023-49092 | rsa | 0.9.10 | not fixed | CVE-2023-49092 |
| CVE-2026-56860 | stdlib | 1.26.5 | 1.26.6 | CVE-2026-56860 |
| CVE-2026-56858 | stdlib | 1.26.5 | 1.26.6 | CVE-2026-56858 |
| CVE-2026-59890 | setuptools | 70.3.0 | 83.0.0 | CVE-2026-59890: Improper Handling of Unicode Encoding |
| CVE-2026-84303 | grpc | 1.83.0 | 1.83.1 | CVE-2026-84303: Improper Handling of Case Sensitivity |